Scope
- Name the business data flow and its owner.
- Select representative, non-sensitive test assets.
- Identify the producer, recipient and enforceable control point.
- Document the condition that should permit or decline use.
Security and governance
- Agree access roles and the handling of credentials.
- Record data minimisation, retention and deletion expectations.
- Define how decisions are logged and reviewed.
- Approve the test plan and rollback path.
Test cases
- Valid policy and evidence: accepted.
- Missing or invalid evidence: declined.
- Copied or replayed payload: declined.
- Revoked or changed policy condition: declined.
- Unavailable dependency: agreed fail-safe behaviour.
Close-out
Review evidence against the agreed criteria, document limitations and decide whether a production design should be explored.
